feat(sync): scheduled upstream-sync that opens PRs per source repo - #8
Merged
Conversation
Active documentation contributions still land in the legacy owncloud/docs-* repos. This adds a daily GitHub Actions workflow that mirrors each upstream branch's modules/ into the mapped monorepo folder and opens one pull request per source repo with the diff. - sync/manifest.yml: branch->folder mapping (single source of truth) - sync/sync-repo.sh: yq-driven mirror of sync_paths, preserves antora.yml - .github/workflows/sync-upstream.yml: schedule + matrix + create-pull-request Mirror mode is stateless and self-correcting; antora.yml and other monorepo-managed files are never overwritten. Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
5 tasks
DeepDiver1975
added a commit
that referenced
this pull request
Aug 21, 2026
…1) (#99) Three open alerts all concern the same transitive js-yaml 4.x copies, which Antora nests under three of its packages: - js-yaml 4.1.1 -> 4.3.1 in @antora/content-aggregator, @antora/playbook-builder and @antora/ui-loader - #10 high — quadratic CPU consumption in !!omap resolution (CVE-2026-59870 not backported), needs >= 4.3.1 - #9 high — YAML merge-key chains force quadratic CPU, needs >= 4.3.0 - #8 medium — quadratic-complexity DoS in merge key handling via repeated aliases, needs >= 4.2.0 The direct js-yaml dependency is already 5.3.0 and is not in any vulnerable range, so a blanket override is wrong here: it would downgrade the safe 5.x direct dependency to the 4.x legacy line. Two major lines are live at once, so the pin is applied per parent instead, leaving the root dependency at 5.3.0. The three Antora packages declare "js-yaml": "~4.1", which cannot reach 4.3.1, and Antora's latest stable release (3.1.15) is already in use — only 3.2.0 pre-releases exist upstream. Overrides are therefore the only route to the patched version without moving to a pre-release Antora. Verified under Node 22 (the version CI uses; the local default is 18): npm ci, npm run antora (exit 0), npm test (17/17 pass), npm run pagefind. The 29 xref errors in the Antora log are pre-existing content issues on main (stale "next@ocis:ROOT:" targets) and are non-fatal — no failure_level is configured in site.yml. All three alerts are fixable and fixed; none are left without a fix. They remain open until this lands on the default branch. Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a scheduled GitHub Actions workflow that keeps the monorepo current with the
legacy
owncloud/docs-*repos, where active documentation contributions stillland. Each run mirrors every mapped upstream branch's
modules/into its monorepofolder and opens one pull request per source repo with the diff.
Why
The monorepo was seeded by a one-time plain copy and had no mechanism to stay
current — upstream edits never reached it. This closes that gap with cloud-only,
token-free automation.
How
sync/manifest.yml— single source of truth for the branch→folder mapping(e.g. each repo's
master→ its in-dev/prerelease folder). Adding a version =one entry here.
sync/sync-repo.sh—yq-driven mirror of thesync_pathsallowlist(
modules). Mirror/replace: upstream wins, stale files removed. Themonorepo-managed
antora.ymlis never touched..github/workflows/sync-upstream.yml— daily (03:00 UTC) +workflow_dispatch; a matrix over the manifest runs each repo in its own joband opens/updates
sync/<repo>viapeter-evans/create-pull-request.Stateless and self-correcting — no SHA baseline, no drift.
Verification done
bash -n+ YAML lint pass.sync-repo.sh docs-webui: produced a real upstream diff,re-run was idempotent, and
content/webui/antora.ymlwas confirmed unchanged.Before enabling the schedule
Confirm the
master→dev-folder rows and the ocis8.0vsmasterchoice insync/manifest.ymlmatch maintainer intent.🤖 Generated with Claude Code